{"id":"CVE-2026-40068","aliases":["GHSA-q5hj-mxqh-vv77"],"url":"https://o3.security/vulnerability/CVE-2026-40068","summary":"Claude Code arbitrary code execution via git worktree commondir trust dialog bypass","details":"Claude Code used the git worktree `commondir` file when determining folder trust but did not validate its contents. By crafting a repository with a `commondir` file pointing to a path the victim had previously trusted, an attacker could bypass the trust dialog and immediately execute malicious hooks defined in `.claude/settings.json`. Exploiting this required the victim to clone a malicious repository and run Claude Code within it, and for the attacker to know or guess a path the victim had already trusted.\n\nUsers on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.\n\nClaude Code thanks [hackerone.com/masato_anzai](https://hackerone.com/masato_anzai) for reporting this issue.","published":"2026-05-05T20:52:26.089Z","modified":"2026-08-12T03:51:18.751106704Z","cvss":null,"epss":{"score":0.00314,"percentile":0.23575,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@anthropic-ai/claude-code","fixedVersion":"2.1.84"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40068.json"},{"type":"ADVISORY","url":"https://github.com/anthropics/claude-code/security/advisories/GHSA-q5hj-mxqh-vv77"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40068"},{"type":"PACKAGE","url":"https://github.com/anthropics/claude-code"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:18.751106704Z"}}